Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1151 discussion

Actual exam question from Isaca's CISA
Question #: 1151
Topic #: 1
[All CISA Questions]

What should an IS auditor evaluate FIRST when reviewing an organization’s response to new privacy legislation?

  • A. Implementation plan for restricting the collection of personal information
  • B. Analysis of systems that contain privacy components
  • C. Privacy legislation in other countries that may contain similar requirements
  • D. Operational plan for achieving compliance with the legislation
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
saado9
Highly Voted 1 year, 7 months ago
D. Operational plan for achieving compliance with the legislation
upvoted 7 times
...
PurpleParrot
Most Recent 1 month, 1 week ago
Selected Answer: B
why not option B? it seems like the first step. operational plan seems a bit high level.
upvoted 1 times
...
Sibsankar
6 months ago
By analyzing the organization's systems that handle personal information, the auditor can identify the specific areas that might be impacted by the new legislation. This helps them assess the potential risks and gaps in compliance. The right answer is B
upvoted 1 times
...
Swallows
7 months, 4 weeks ago
Selected Answer: B
The Privacy Component is the element of a system that collects, processes, stores, and transmits personal information subject to privacy laws. Analyzing a system that contains a privacy component should identify what types of personal information are involved, where it resides, how it is used, who has access to it, and what risks and threats it faces. An analysis of the system containing the privacy component is essential to determine the scope and impact of new privacy laws on the organization's systems and processes.
upvoted 1 times
...
KAP2HURUF
10 months, 3 weeks ago
Selected Answer: D
The operational plan (option D) typically encompasses various aspects, including the implementation plan for specific measures like restricting the collection of personal information. By starting with the operational plan, an IS auditor gains a comprehensive overview of the organization's approach, timelines, and key strategies for compliance. It sets the stage for a more detailed examination of specific elements, such as the implementation plan mentioned in option A.
upvoted 1 times
...
FAGFUR
1 year ago
Selected Answer: D
When reviewing an organization's response to new privacy legislation, the IS auditor should first evaluate the operational plan for achieving compliance with the legislation. The operational plan outlines the specific actions and measures that the organization intends to take to meet the requirements of the new privacy legislation. Understanding the operational plan is crucial because it provides insights into how the organization is addressing compliance, allocating resources, and implementing necessary changes to adhere to the legal requirements. It includes details about processes, controls, and timelines for achieving compliance.
upvoted 2 times
KAP2HURUF
10 months, 3 weeks ago
Some answer here is confusing, i also prefr chatgpt and elaborate more explanation there not only use got first answer. I also ask ehy other options are false. Good luck
upvoted 1 times
...
...
SuperMax
1 year, 1 month ago
Selected Answer: D
D. Operational plan for achieving compliance with the legislation. The operational plan outlines how the organization intends to meet the requirements of the new privacy legislation. It includes specific actions, timelines, responsible parties, and resource allocations for achieving compliance. Before diving into the technical or system-related aspects (options A and B) or exploring international legislation (option C), it's crucial to understand how the organization intends to implement and manage its compliance efforts, as this sets the foundation for the entire privacy program.
upvoted 2 times
...
BabaP
1 year, 6 months ago
Selected Answer: A
A is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...